CVE-2026-100673
Published 26 September 2026 · tracked since 27 September 2026
Description
The Grav Data Manager plugin (getgrav/grav-plugin-datamanager) versions 1.0.1 through 1.4.4 render stored data entries in the item-detail view (admin/templates/partials/item.html.twig) without escaping, applying Twig's `raw` filter — in some cases after a striptags('<br>') call that PHP's strip_tags
References
- NVD — National Vulnerability Database
- CVE.org record (MITRE)
- CISA Known Exploited Vulnerabilities catalog
Latest tracked vulnerabilities
- CVE-2026-93348 HIGH 8.1
- CVE-2026-88808 HIGH 8.8
- CVE-2026-101861 MEDIUM 4.1
- CVE-2026-101079 LOW 2.8
- CVE-2026-93539 MEDIUM 5.4
- CVE-2026-96538
- CVE-2026-93537 MEDIUM 6.5
- CVE-2026-82929
- CVE-2026-82935
- CVE-2026-82323 HIGH 8.1